Passes don’t make a purge. Reaching the whole medium does.
IEEE 2883-2022 §6.5.1
A software overwrite goes through the host interface, so it physically cannot reach a sector the drive has already retired. Under both IEEE 2883 and NIST SP 800-88r2 that makes it a Clear — on every media type, at three passes or thirty-five. Tools that run a multi-pass overwrite and print “Purge” on the certificate are mislabelling the result. We label it Clear.
We never downgrade silently.
IEEE 2883-2022 §6.1, §8.4.3.1
The engine tries the purge techniques in order — cryptographic erase, block erase, sanitize overwrite, ATA Enhanced Secure Erase. If every one fails the drive is marked FAILED and the certificate states that destruction is required. It does not quietly fall back to an overwrite and call the job done.
We prove the data was there, and then wasn’t.
IEEE 2883-2022 §8.4.2.2, §8.4.3.2
Offset-bound markers are written to sampled locations before sanitizing, then read back afterwards. Reading a drive afterwards and finding it blank proves little — a drive that was never written also looks blank. This proves that this specific data was destroyed.
Hidden areas are exposed before we start.
IEEE 2883-2022 §8.4.2.2(a)
Access limits are reset before sanitization begins: HPA, DCO, Accessible Max Address, Zone Activation, Storage Element Depopulation and TCG locking ranges. An overwrite that ignores a Host Protected Area leaves data behind while reporting success. This is not an optional setting.
Verification and validation are different, and we do both.
NIST SP 800-88r2 §4.5.1, §4.5.2
Verification asks what happened — command status, errors, anomalies, and drive health after the wipe. Validation asks whether that is good enough, and returns an explicit ACCEPTED or REJECTED. We re-read SMART after the wipe and will reject a sanitization when a host overwrite was used on flash, when sectors are pending reallocation, when HPA or DCO could not be removed, or when the drive reports a SMART failure. A rejected wipe is not certified as complete.
Sampling follows the standard’s own numbers.
IEEE 2883-2022 §7.1, §7.3, §7.4
10,000 subsections, at least two pseudo-random locations in each, plus the first and last addressable location — 20,002 locations per drive, deterministic per device so an auditor re-running it checks the same places. A Purge gets full verification of the addressable media rather than a spot check. The exception is honest: after a cryptographic or block erase the contents are unpredictable by design, so §7.4 says full verification is not effective — we fall back to the known-pattern check and say so on the certificate.